Skip to main content
Self-Assessment

Where Is Your Organization on the AI Security Maturity Curve?

10 questions across 5 dimensions. 3 minutes. Get a maturity score, dimensional breakdown, and a personalized Shield tier recommendation — no email required.

The Five Maturity Levels

Every organization fits somewhere on this curve. The goal isn't perfection — it's knowing your position and taking the next step.

1

Ad Hoc

1.0 – 1.9

No formal AI security program. Tools are used ad hoc with no visibility, policy, or monitoring. Risk is unmanaged.

2

Aware

2.0 – 2.9

Basic awareness exists. Some informal guidelines documented. Enforcement is manual and inconsistent. Gaps are widespread.

3

Managed

3.0 – 3.9

Formal AI security policy in place. Basic monitoring and tool inventory exist. Automated detection is partial. Compliance mapping has begun.

4

Proactive

4.0 – 4.9

Automated redaction and inspection in production. Audit trails are tamper-evident. Compliance evidence packages are exportable. Security is embedded into developer workflows.

5

Optimized

5.0

Continuous improvement culture. AI security metrics are tracked and reviewed. Incident response is practiced. The organization leads its industry in AI security posture.

Ready to move up the maturity curve?

Shield runs locally on your machine — one env var, immediate redaction, and a tamper-evident audit trail. Know what leaves your network before the models do.

View Shield Request a Demo

Frequently Asked Questions

A maturity model is a framework that helps organizations assess their current capabilities and identify a path for improvement. This model evaluates your AI security posture across five dimensions: governance, visibility, data protection, threat detection, and compliance. Each dimension is scored from 1 (Ad Hoc) to 5 (Optimized), giving you a clear picture of where you stand and what to prioritize next.

Traditional security maturity models (like NIST CSF or CMMC) don't account for the unique risks of LLM usage: prompts that carry secrets past network perimeters, model providers that may retain or train on your data, and injection attacks that bypass conventional input validation. This model is purpose-built for the AI era — it evaluates controls specific to LLM API calls, not generic network security.

Shield Foundation ($10K) addresses the gap between Ad Hoc/Aware and Managed — it provides the inspection layer, automated redaction, and audit trails that move you from manual to automated. Shield Compliance ($25K) bridges Managed to Proactive with compliance mapping, tamper-evident logging, and injection defense. For organizations at the Optimized level, enterprise features like custom filter packs and SIEM integration extend your existing lead.

The model scores each dimension independently, so you'll see a breakdown showing where you're strongest and weakest. The overall average determines your primary level, but the dimensional scores are where the actionable insights live — focus your improvement efforts on the lowest-scoring dimensions first.

AI adoption moves fast. New tools appear monthly, new attack vectors emerge, and compliance requirements evolve. Reassess quarterly at minimum. If you're undergoing a major AI initiative — deploying a new LLM-powered product, expanding to a regulated market, or onboarding a large team — reassess before and after the change.

The assessment itself is a self-evaluation tool, not an auditor-certified report. However, the results — combined with Shield's tamper-evident audit logs and compliance mapping — form a strong foundation for auditor conversations. Shield Compliance customers can export evidence packages that map every control to specific SOC 2, HIPAA, GDPR, and ISO 27001 clauses.